Criminology → Volume 2, Issue 1

Financial Fraud Through the Theft of Bank Card Data: A Systematic Analytical Review

29.06.2026 Research EN 🔓 Open Access 👁 4 · 📥 1

Annotation / Abstract

Abstract. Theft of bank payment card data is among the most widespread forms of financial fraud, yet the techniques involved are frequently studied in isolation rather than as components of a single monetization process. This article addresses that gap by systematizing, within one analytical framework, the principal methods of obtaining payment card credentials – the card number, expiry date, security code, and one-time confirmation password – together with the subsequent use of the stolen data and the mechanism through which financial harm accrues. The study is analytical rather than empirical: it applies comparative, systematic, and descriptive-statistical approaches to a body of secondary material comprising peer- reviewed publications, industry security reports, and international legal instruments. The analysis classifies the theft techniques by their technical features, distinguishing device-based methods (skimming and shimming) from digital methods (phishing, fake payment pages, and electronic skimming), and then traces how the resulting credentials circulate through underground carding markets before being converted into monetary loss and proposes directions for further research, particularly empirical measurement in the context of Uzbekistan.

Full text

The scholarly problem is that the methods of card-data theft (phishing, skimming, e-skimming, carding, and others) are often examined separately in the literature, while their connection as a single economic chain – from theft through to the monetization of stolen data on the carding market – remains insufficiently systematized. This fragmentation in turn leads to the piecemeal application of protective measures.

This article is analytical (review) in character: it does not conduct a new empirical experiment but rather synthesizes existing scholarly literature, industry reports, and international instruments through comparative and systematic analysis in order to generalize the methods of card-data theft and their consequences. The aim of the study is to systematize the methods of stealing bank card data and to analyze their role in the formation of financial harm. From this aim, the following objectives were defined:

  1. to analyze and classify the principal methods of card-data theft (phishing, fake payment pages, skimming/e-skimming, carding, CVV/OTP deception);
  2. to examine the subsequent use of stolen data and its circulation on the carding market;
  3. to generalize the mechanism by which financial harm is formed;
  4. to outline the context of legal qualification and to formulate practical recommendations.

This analytical work is based not on empirical testing but on the systematic study of existing sources and financial-sector reports. The following methods were applied:

  • Comparative-analytical method, used to compare the methods of card-data theft with one another according to their technical features and effectiveness.
  • Systematic approach, used to consider individual methods as links in a single economic chain extending from theft to monetization.
  • Descriptive-statistical analysis, used to aggregate the quantitative data contained in reports on financial fraud.
  • Formal-legal method, used to delineate the context of the legal qualification of the conduct concerned.

Source base. Several categories of source were drawn upon: (a) peer-reviewed international scholarly publications (academic research on the cloning of EMV cards, defence against e-skimmers, and the detection of payment fraud through machine learning) [6, 7, 8, 9]; (b) industry and security reports and statistical sources [1, 2, 3, 10, 11, 12, 13, 14, 15]; (c) official and academic sources relating to Uzbekistan (statistics of the Ministry of Internal Affairs Cybersecurity Centre and national peer-reviewed analyses) [4, 5, 16]; and (d) international and national legal instruments – the Council of Europe Convention on Cybercrime [17] and the Criminal Code and sectoral laws of the Republic of Uzbekistan [18, 19, 20, 21]. The legal norms should be additionally verified by the author against the current redaction via lex.uz.

A limitation of the study is that the statistical indicators cited reflect the state of affairs at the time the sources were published and remain relative in a rapidly changing field.

A general framework for card-data theft

It is expedient to divide the methods of stealing payment card data into two broad groups: (1) physical/device-based methods – skimming and shimming, that is, the capture of data from physical devices such as ATMs or payment terminals; and (2) digital/online methods – phishing, fake payment pages, and e-skimming, that is, the acquisition of data within the internet environment. Both groups ultimately produce the same product – saleable card credentials – and therefore feed into a common “carding” economy (Section 3.5).

Phishing and fake payment pages

Phishing is a method of deceiving a user, in the name of a trusted organization (a bank, payment system, or government service), into voluntarily entering card credentials. According to the Verizon [15] Data Breach Investigations Report, phishing remains one of the principal vectors in credential-related breaches, and users often respond to a phishing message in less than a minute: on average 21 seconds elapse before a link is clicked and a further 28 seconds before data is entered [15]. In its analysis of the finance sector, ENISA [11] notes that phishing, smishing (phishing via SMS), and vishing (deception via telephone call) are the principal forms of social-engineering attack, with individuals targeted in approximately 38 per cent of cases and banks in 36 per cent.

A fake payment page is the technical manifestation of phishing, operating through a page that imitates the interface of a legitimate bank or payment system. When a user is directed to such a page (typically via a malicious link), they enter the card number, expiry date, and CVV code, and these data are transmitted directly to the attacker's server. The ENISA [11] report specifically emphasizes the large-scale theft of card data resulting from the impersonation of banks and from successful phishing and smishing.

References

References / Foydalanilgan manbalar

  1. The Motley Fool. (2025). Identity theft and credit card fraud statistics for 2025. https://www.fool.com/money/research/identity-theft-credit-card-fraud-statistics/
  2. H25. (2024). Stolen credit cards for sale: How the dark-web carding economy works. https://www.h25.io/dark-web/stolen-credit-cards-for-sale-how-the-dark-web-carding-economy-works/
  3. Trend Micro. (2023). Over 30 million stolen credit card records being sold on the dark web. https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/over-30-million-stolen-credit-card-records-being-sold-on-the-dark-web
  4. Gazeta.uz. (2025, May 31). Cybercrimes in Uzbekistan increase 68-fold in five years (based on data of the Cybersecurity Centre of the Ministry of Internal Affairs of the Republic of Uzbekistan). https://www.gazeta.uz/en/2025/05/31/cybercrime/
  5. Kun.uz. (2025, December 23). Cybercrime cases surge elevenfold across Uzbekistan. https://kun.uz/en/news/2025/12/23/cybercrime-cases-surge-elevenfold-across-uzbekistan
  6. Bond, M., Choudary, O., Murdoch, S. J., Skorobogatov, S., & Anderson, R. (2014). Chip and skim: Cloning EMV cards with the pre-play attack (arXiv:1209.2531). arXiv. https://arxiv.org/pdf/1209.2531
  7. Cherif, A., Badhib, A., Ammar, H., Alshehri, S., Kalkatawi, M., & Imine, A. (2023). Credit card fraud detection in the era of disruptive technologies: A systematic review. Journal of King Saud University – Computer and Information Sciences, 35(1), 145–174. https://doi.org/10.1016/j.jksuci.2022.11.008
  8. Strelcenia, E., & Prakoonwit, S. (2023). Improving classification performance in credit card fraud detection by using new data augmentation. AI, 4(1), 172–198. https://doi.org/10.3390/ai4010008
  9. [CITATION NEEDED – author to supply complete bibliographic details for “NAISS: A reverse proxy approach to mitigate MageCart's e-skimmers in e-commerce,” Computers & Security, Elsevier.] https://www.sciencedirect.com/science/article/pii/S0167404824000981
  10. Clearly Payments. (2024). Credit card fraud statistics in 2024 for USA. https://www.clearlypayments.com/blog/credit-card-fraud-statistics-in-2024-for-usa/
  11. ENISA. (2025). ENISA threat landscape: Finance sector, January 2023 to June 2024. European Union Agency for Cybersecurity. https://www.enisa.europa.eu/sites/default/files/2025-02/Finance%20TL%202024_Final.pdf
  12. Focal. (n.d.). What is card skimming and how to stay safe from ATM fraud? Retrieved June 4, 2026. https://www.getfocal.ai/blog/what-is-card-skimming
  13. Imperva. (n.d.). What is Magecart: Attack examples & prevention techniques. https://www.imperva.com/learn/application-security/magecart/
  14. The Hacker News. (2026, January). Long-running web skimming campaign steals credit cards from online checkout pages. https://thehackernews.com/2026/01/long-running-web-skimming-campaign.html
  15. Verizon. (2024). 2024 Data Breach Investigations Report: Executive Summary. https://www.verizon.com/business/resources/reports/2024-dbir-executive-summary.pdf
  16. World Bulletin of Management and Law. (2025). Cybercrimes committed through phishing and ransomware attacks in Uzbekistan: Analysis and protective measures. [CITATION NEEDED – author(s) name(s) to supply]. https://scholarexpress.net/index.php/wbml/article/view/5179
  17. Council of Europe. (2001). Convention on Cybercrime (ETS No. 185). https://rm.coe.int/1680081561
  18. Criminal Code of the Republic of Uzbekistan (1994, as amended). Lex.uz. [VERIFY against current redaction at lex.uz]. https://lex.uz/docs/-111453
  19. Law on Banks and Banking Activity of the Republic of Uzbekistan (No. ZRU-580, November 5, 2019). Lex.uz. [VERIFY against current redaction at lex.uz]. https://lex.uz/docs/-4581969
  20. Law on Payments and Payment Systems of the Republic of Uzbekistan (No. ZRU-578, November 1, 2019). Lex.uz. [VERIFY against current redaction at lex.uz]. https://lex.uz/docs/-4574008
  21. Law on Personal Data of the Republic of Uzbekistan (No. ZRU-547, July 2, 2019). Lex.uz. [VERIFY against current redaction at lex.uz]. https://lex.uz/docs/-4396419
  22. IDlayr. (n.d.). The problem with SMS OTPs: Why this 2FA method isn't as secure as you think. Retrieved June 4, 2026. https://idlayr.com/blog/sms-otp-2fa-fraud/
  23. TechCrunch. (2024, May 13). “Got that boomer!”: How cybercriminals steal one-time passcodes for SIM swap attacks and raiding bank accounts. https://techcrunch.com/2024/05/13/cyber-criminals-stealing-one-time-passcodes-sim-swap-raiding-bank-accounts/
  24. Elliptic. (2023). Largest stolen credit card market shunned by cybercriminals after alleged “exit scam.” https://www.elliptic.co/blog/analysis/largest-stolen-credit-card-market-shunned-by-cybercriminals-after-alleged-exit-scam
🔍 View online 📥 Download PDF

APA

Choriyev, Ulugbek (2026). Financial Fraud Through the Theft of Bank Card Data: A Systematic Analytical Review. Criminology, 2(1), 137–143. https://doi.org/

Vancouver

Choriyev, Ulugbek. Financial Fraud Through the Theft of Bank Card Data: A Systematic Analytical Review. Criminology. 2026;2(1):137-143.